Jump to content

Locking down desktops and mandatory profiles


Recommended Posts

Posted

Hi there

 

Just joined this after seeing the letter in PC Pro a month back. Well done.

 

I'm trying to set up a new network at a Primary School which consists of the following so far:

 

Windows 2000 Server SP4.

Clients running XP Pro SP2.

Domain + Active Directory + GPOs to configure PCs.

(The GPMC for XP and WS 2003 makes GPO management a lot easier!)

Redirected My Documents via GPO.

 

I'm now trying to arrive at the best way to stop those meddling fingers by locking things down tightly. What I want to do is use mandatory profiles on the server, i.e. by changing NTUser.DAT to NTUser.MAN. My questions are:

 

- Is this a typical scenario that people are using in schools?

- What are the implications for installation of new software (i.e. additions to start menus, new icons, etc) if the desktops use mandatory profiles?

- Is there another way?

 

All help gratefully received.

 

Thanks

 

Andy

Posted

Hmmm, I'd probably look at introducing Group Policies to lock down desktops for students and staff who can be a bigger pain.

 

I'm now looking into Group Policies for the school I'm working at, but I've got alot of other mini projects going on as well. Staff don't want a massive change to the system yet as we are being Ofsteaded very soon.

 

I might be wrong but I believe that GPO's are the best route of locking down the system without spending money.

Posted

Hi Andrew,

 

There have been a few threads on Profiles and all pretty much say the same, NO PROFILES

 

Although it is a matter of taste and how many users you have but in our case we have 1600 + users and if you use mandatory profiles info is being carried across the network at logon will slow down that network to a crawl yes this was happening when I took over.

 

I have basically setup the following:

 

1 - Using an unattended XP install which has been slimmed down (from 568Mb to 234Mb) and slipstreamed with SP2 + Hotfixes. Slimming down the source of XP is good on two counts it makes the install faster as there are very few files to copy and it also removes the programs that cause the problems in the first place, for example MSN, MEssanger, Games, etc.

2 - Logon script removes all unwanted shortcuts from the menus for both all users and the logged on user.

3 - Using GPO to restrict everything else.

 

Result: A completelt locked down desktop that when a stundent logs in all they have is Start > LogOff & Start > Programs with only the software that they can use visible.

 

Software is deployed view GPO at machine startup so no user actually needs to be logged in for the install to take place.

 

Right click context menus have been removed from everywhere, no access to local drives at all just the network share for thier personal folder and trhe assignments folder, students cannot install software nor can they run certain files from pen drives/memory sticks.

 

All this and not a profile in site.....

Posted

I have a mandatory profile set up for pupils, and locked down with Group Policy.

Staff have roaming profiles and logon is still down to only a few seconds, for pupils and staff.

I found a combination of a mandatory profile and use of group policy works best for us.

Posted

Thanks everyone for the quick feedback.

 

There have been a few threads on Profiles and all pretty much say the same, NO PROFILES

 

I did look through the threads but the ones I saw seemed to be anti-roaming profiles rather than mandatory ones.

 

Although it is a matter of taste and how many users you have but in our case we have 1600 + users and if you use mandatory profiles info is being carried across the network at logon will slow down that network to a crawl yes this was happening when I took over.

 

I will only have around 30-40 PCs max. I assumed that by redirecting My Documents via GPO the bulk of the data would not get transferred at logon.

 

2 - Logon script removes all unwanted shortcuts from the menus for both all users and the logged on user.

 

Any chance of seeing an example of what this script looks like?

 

3 - Using GPO to restrict everything else.

 

Result: A completelt locked down desktop that when a stundent logs in all they have is Start > LogOff & Start > Programs with only the software that they can use visible.

 

I must be missing something here. I can find a GPO for most things but I can't find anything to stop files and icons being saved on to or moved on the desktop. How do you achieve that via GPO? That was one of the main reasons I was looking at a mandatory profile.

 

Right click context menus have been removed from everywhere, no access to local drives at all just the network share for thier personal folder and trhe assignments folder, students cannot install software nor can they run certain files from pen drives/memory sticks.

 

All this via GPO?

 

Thanks for the help, much appreciated.

 

Andy

Posted

@Andrew:

 

Attached is an Excel Spreadsheet of all GPO's available under Windows 2003 and is broken down into easy to search sections this should help you find what you need.

 

I would concentrate on the following areas:

 

User Configuration -> Administrative Templates -> Start Menu & Task Bar

User Configuration -> Administrative Templates -> Desktop

 

This will control all aspects of the desktop itself and the task bar / start menu.

 

You will need to go a stage further and hit the following:

 

User Configuration -> Administrative Templates -> Windows Components -> Windows Explorer

 

This will allow you to control local drive access, and remove all non essential options from the menus i.e. map network drive, remove windows hot keys etc...

 

Hope it helps

 

File Can Be Found Here

Posted
I have a mandatory profile set up for pupils, and locked down with Group Policy.

Staff have roaming profiles and logon is still down to only a few seconds, for pupils and staff.

I found a combination of a mandatory profile and use of group policy works best for us.

 

We use exactly the same for our users as above. 1600 + kids and 140 staff.

 

 

Works well for us with no problems......The thought of kids having roaming profiles................no thanks.

Posted

@Andrew - I notice ICTNUT refers to server 2003 when you state you have server 2000.

 

You can access 2003 policies using the correct updates to 2000 server [links please ppl! ;)], and using the GPMC from an XP SP2 workstation. This is necessary to completely lock down an XP SP2 client, and the newest ADM's for 2003 server/XP SP2 will work for all previous OS versions.

Posted
Attached is an Excel Spreadsheet of all GPO's available under Windows 2003 and is broken down into easy to search sections this should help you find what you need.

 

Thanks for the spreadsheet, really useful to see it all in one place.

 

User Configuration -> Administrative Templates -> Start Menu & Task Bar

User Configuration -> Administrative Templates -> Desktop

 

This will control all aspects of the desktop itself and the task bar / start menu..

 

I've already made use of many of these and they seem to do the job but the one thing I can't stop is the ability to save shortcuts & icons or move things on the desktop itself. "Don't save settings on exit" doesn't prevent it". Any idea which one should I use for that, as it's not obvious to me after reading through everything.

 

@Andrew - I notice ICTNUT refers to server 2003 when you state you have server 2000.

 

You can access 2003 policies using the correct updates to 2000 server [links please ppl! ;)], and using the GPMC from an XP SP2 workstation. This is necessary to completely lock down an XP SP2 client, and the newest ADM's for 2003 server/XP SP2 will work for all previous OS versions.

 

You're right, I am using 2000 but I do use the GPMC on one of the XP SP2 machines to manage everything. I'd be interested to know what the extra updates to 2000 are and what extra lock-down they provide.

 

Thanks again.

 

Andy

Posted
I have a mandatory profile set up for pupils, and locked down with Group Policy.

Staff have roaming profiles and logon is still down to only a few seconds, for pupils and staff.

I found a combination of a mandatory profile and use of group policy works best for us.

 

Thanks for this info. Going back to one of my earlier questions, if you do use mandatory profiles, how does the installation of new software, new icons, start menu items, etc get affected. Surely the use of NTUser.MAN prevents any updates or other changes to these things?

 

Andy

Posted

Any new software installed (which can also be done by Group Policies ... search in the forums for Group Policy or GPOs for other threads) usually sticks the start menu items in the All Users profile which applies to everyone when they logon as an extra to whatever profile you have (mandatory, roaming or local).

 

Sometimes it doesn't, but you can move the icons afterwards so they are in the right place (c:\documetns and settings\all users\start menu, etc)

Posted

Andrew Wrote:

 

Thanks for this info. Going back to one of my earlier questions, if you do use mandatory profiles, how does the installation of new software, new icons, start menu items, etc get affected. Surely the use of NTUser.MAN prevents any updates or other changes to these things?

 

If i want to amed the desktop, icons, start menu etc i log on with the user used to creat the mandatory profile. edit the profile and upload it back to the server with the changes.

Posted

When a user logs into an XP or W2K Pro box it has the following settings from the AD take effect.

 

Firstly those specified by any computer policies from the GPOs (these actually happen when the machine starts up)

Then you have the user policies (as the user logs in)

You can actually have more computer policies here by using a feature/bug called loopback (DON'T!!! when it goes wrong it goes majorly wrong ... IME)

Then you have any local settings from the computer itself.

Finally you have profiles.

Whatever profile you have, roaming, mandatory or local, it first takes any settings it needs from the "all users" profile (stored on the local machine) and the "default users" profile (also on the local machine in a hidden folder). It then applies the user's own profile.

 

So, it makes no difference that NTUser.MAN prevents updates ... the updates are applied to the "all users" or "default user" settings.

 

HTH

Posted
and the "default users" profile (also on the local machine in a hidden folder).

 

Or from the netlogon share where it is the first location to be checked before the local folder. Not advisable though as it will work on ALL your desktop pc's.

Posted

Thanks all for the latest replies. That clarifies things regarding NTUser.MAN. I'd still be interested in a specific GPO setting that stops icons being added to or moved on the desktop. I can't spot it and I've tried a fair few as well.

 

Andy

Posted

I agree with ICTNUT, except I don't know what he means when he says there's no profiles. I don't see how it's possible to do without profiles.

 

I used to use a mandatory profile (ntuser.man) but it caused a lot of problems. I now have a desktop heavily locked down with GP, and roaming profiles. It works for me.

 

As for the desktop: Just use folder redirection to redirect the all the pupils' desktops to a single shared folder. Make it 'read only' to them with NTFS permissions. Do the same with the start menu folder. This is what I do.

 

Andrew - I'll send you a dump of my pupils group policy object giving a thoroughly locked down desktop.

 

To summarise, use roaming profiles and GPO's to lock down the desktop. That's my advice anyway - it works for me.

  • 2 weeks later...
Posted
Andrew - I'll send you a dump of my pupils group policy object giving a thoroughly locked down desktop.

 

Thanks for all the extra feedback. I've sent you an email with my address details.

 

Regards

 

Andy

  • 2 weeks later...
Posted

@ICTNUT:

 

If you don't configure roaming profiles, what happens to any information stored in the user registry when users log off? Do you use the same strategy form staff and students?

Posted
The way it works with AD is that a local profile is created using the default user profile as a template. This profile will be created on every PC they logon to from the local defualt user profile, or the network one if specified. As for the registry, that is what GPOs are. A customised registry for every user. The AD user logs on, takes whatever settings are set for the default user, including printers etc and creates a ntuser.dat file in the local profile. The rest of the profile information is provided via GPOs from active directory, and these will change as and when the GPO does. When the next user logs on they will have a different registary loaded for them depending on their group policy membership. Think of it as a new registery being loaded for every user.
Posted

Yes, but what I'm getting at is that when a user has a roaming profile, any changes he makes to his environment are saved in his personal registry. These settings are then available at any PC he logs on to. It would seem that unless you use roaming profiles (even if you redirect every possible folder; MyDocs,Desktop,StartMenu,AppData), anything saved in the user registry will be lost when the user logs off.

 

I wonder what the effect of this will be on applications like Microsoft Office, which install a significant number of user registry entries (courtesy of Windows Installer). Will these entries be recreated each time the user logs onto a new PC?

Posted

@ajbritton: You are correct, these changes are lost. This is precisely why you configure the 'Default User' profile by simply running and configuring all the apps first.

 

When a user logs on, the Default User profile is loaded (loading your standard settings) and you then delete the local user profile on logoff.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...